Data protection in USA is governed by a patchwork of federal sector-specific laws and a growing body of state-level comprehensive privacy statutes, rather than a single national framework. For international businesses and domestic companies alike, this fragmented structure creates real compliance complexity: obligations differ by industry, by the type of data processed, and by the state in which consumers reside. This guide maps the current federal and state landscape, explains key obligations, identifies the authorities that enforce them, and outlines what companies must do to remain compliant.
Unlike the European Union';s unified General Data Protection Regulation, the United States has no single omnibus federal privacy law. Instead, Congress has enacted a series of sector-specific statutes, each administered by a dedicated regulator.
The Health Insurance Portability and Accountability Act, commonly known as HIPAA, governs the handling of protected health information by covered entities - hospitals, insurers, healthcare providers - and their business associates. HIPAA imposes strict requirements on data access, storage, breach notification, and the use of patient data for secondary purposes. Violations can result in civil monetary penalties tiered by culpability, reaching into the tens of millions of dollars for the most serious breaches.
The Gramm-Leach-Bliley Act, or GLBA, applies to financial institutions and requires them to explain their data-sharing practices to customers and to implement a written information security programme. The Federal Trade Commission and federal banking regulators share enforcement authority under GLBA, and recent amendments have tightened the technical safeguards required of covered entities.
The Children';s Online Privacy Protection Act, known as COPPA, restricts the collection of personal data from children under thirteen without verifiable parental consent. The FTC enforces COPPA and has pursued significant enforcement actions against technology platforms in recent years.
The Family Educational Rights and Privacy Act, or FERPA, protects student education records held by schools receiving federal funding. These sector-specific laws collectively cover large portions of the economy, but they leave significant gaps - particularly for general consumer data held by technology companies, retailers, and data brokers.
In the absence of federal omnibus legislation, state legislatures have moved aggressively. The California Consumer Privacy Act, as amended by the California Privacy Rights Act, remains the most influential state law and effectively sets a national baseline for many large businesses. The CCPA/CPRA grants California residents rights to know, delete, correct, and opt out of the sale or sharing of their personal information. It also introduced the concept of sensitive personal information as a distinct category requiring heightened protection, and it established the California Privacy Protection Agency as a dedicated enforcement body with rulemaking authority.
Beyond California, a substantial number of states have enacted their own comprehensive privacy statutes. Virginia';s Consumer Data Protection Act, Colorado';s Privacy Act, Connecticut';s Data Privacy Act, Texas';s Data Privacy and Security Act, and laws in Florida, Montana, Oregon, and several other states have all entered into force or are in the process of doing so. While these laws share a common architecture - consumer rights, controller obligations, data protection assessments, opt-out rights for targeted advertising - they differ in important details: thresholds for applicability, definitions of sensitive data, private rights of action, and cure periods.
A common mistake for international businesses entering the US market is to assume that compliance with one state law equals compliance across all states. In practice, a company processing data of residents from multiple states must map its obligations state by state. The differences are material. For example, some states grant consumers a private right of action for certain violations, while others vest enforcement exclusively in the state attorney general. Some states exempt employee data; others do not.
Many businesses underestimate the compliance burden of the multi-state patchwork. A practical approach is to identify the most demanding applicable law - typically California';s CCPA/CPRA - and build a programme around that standard, then layer in state-specific requirements where they diverge.
Regardless of which specific laws apply, several core obligations recur across the US data protection landscape.
Privacy notices and transparency. Businesses must provide clear, accessible privacy notices describing what data they collect, how it is used, with whom it is shared, and how consumers can exercise their rights. Under CCPA/CPRA, the notice must be presented at or before the point of data collection. A non-obvious requirement is that the notice must also describe any financial incentives offered in exchange for personal data.
Consumer rights fulfilment. State privacy laws require businesses to respond to consumer requests - to access, delete, correct, or port their data - within defined timeframes, typically forty-five days with a possible extension of a further forty-five days. Businesses must establish verified request mechanisms and train staff to handle them. Failure to respond within the statutory window is itself a violation, independent of the underlying data practice.
Data protection assessments. Several state laws, including those of Virginia, Colorado, and Connecticut, require businesses to conduct and document data protection impact assessments before undertaking processing activities that present heightened risk - such as targeted advertising, the sale of personal data, or profiling that produces legal or similarly significant effects. These assessments must be retained and made available to regulators on request.
Contracts with service providers and processors. Businesses must ensure that contracts with third parties who process personal data on their behalf include specific data protection terms. Under CCPA/CPRA, contracts with service providers must prohibit the service provider from retaining, using, or disclosing personal information outside the scope of the business relationship. A common mistake is to rely on legacy vendor agreements that predate current state law requirements.
Opt-out mechanisms for targeted advertising and data sales. State laws uniformly require businesses to offer consumers a clear mechanism to opt out of the sale of their personal data and the use of their data for targeted advertising. Many states also require businesses to recognise opt-out preference signals, such as the Global Privacy Control, without requiring the consumer to submit a separate request.
Data security. The FTC';s authority under Section 5 of the FTC Act, which prohibits unfair or deceptive acts and practices, has been used extensively to require businesses to implement reasonable data security measures. The FTC';s updated Safeguards Rule under GLBA sets detailed technical requirements for financial institutions. Most state privacy laws also impose a general obligation to implement reasonable administrative, technical, and physical safeguards proportionate to the volume and sensitivity of data processed.
If your business processes data of US residents and you are uncertain which obligations apply to your specific situation, contact info@vlolawfirm.com. We can help structure the compliance programme correctly from the outset.
Data protection in USA is enforced by a constellation of federal and state bodies, each with distinct jurisdiction and enforcement tools.
The Federal Trade Commission is the primary federal privacy enforcer for most commercial entities not subject to sector-specific regulation. The FTC brings enforcement actions under its Section 5 authority and under specific statutes such as COPPA and GLBA. FTC orders typically require companies to implement comprehensive privacy programmes, submit to independent audits for extended periods, and pay civil penalties where statutory authority exists. Recent FTC enforcement has focused on data brokers, health data practices, and the use of personal data in algorithmic systems.
The California Privacy Protection Agency is the first dedicated state privacy regulator in the United States. It has rulemaking authority under CPRA and can impose administrative fines of up to a specified amount per violation, with higher penalties for violations involving children';s data. The agency has signalled active enforcement priorities including automated decision-making, sensitive data practices, and dark patterns in consent interfaces.
State attorneys general across the country enforce their respective state privacy laws. Several attorneys general have brought high-profile actions against technology companies, data brokers, and healthcare organisations. The trend is toward coordinated multi-state enforcement, which amplifies the practical risk for companies that operate nationally.
Sector-specific regulators - including the Department of Health and Human Services for HIPAA, federal banking regulators for GLBA, and the Department of Education for FERPA - maintain their own enforcement programmes. HIPAA enforcement in particular has intensified, with the Office for Civil Rights pursuing both large covered entities and smaller healthcare providers.
Penalties across the US data protection landscape vary widely. HIPAA civil monetary penalties are tiered and can reach substantial sums for wilful neglect. State privacy law penalties are typically assessed per violation or per consumer affected, and in the context of large-scale data processing, aggregate exposure can be significant. The FTC has secured multi-billion dollar settlements in major enforcement actions, though these represent the upper end of outcomes for the largest platforms.
For international businesses, data protection in USA raises a distinct set of cross-border questions. The United States is not subject to the EU';s adequacy framework in the same way as countries that have received an adequacy decision. The EU-US Data Privacy Framework, which provides a mechanism for transfers of personal data from the EU to certified US organisations, is the current operative instrument for transatlantic data flows. US companies that wish to receive personal data from the EU must self-certify to the Department of Commerce under the Framework';s principles, which include notice, choice, accountability for onward transfer, security, data integrity, access, and recourse.
A practical scenario: a European company establishing a US subsidiary and transferring employee or customer data to that subsidiary must ensure either that the subsidiary is certified under the EU-US Data Privacy Framework or that an alternative transfer mechanism - such as standard contractual clauses - is in place. Relying on informal arrangements or assuming that data flows within a corporate group are automatically permissible is a common and costly mistake.
A second scenario: a US-headquartered company that collects data from EU residents through a website or app must comply with the GDPR in addition to applicable US state laws. The two frameworks impose overlapping but not identical obligations. GDPR requires a lawful basis for each processing activity, imposes strict rules on consent, and requires the appointment of a Data Protection Officer in certain circumstances. US law generally does not require a DPO, though some companies appoint one voluntarily to manage their global programme.
For companies processing data subject to both frameworks, the practical approach is to identify the more stringent requirement on each point and build to that standard, documenting the rationale for each design choice. This approach reduces the risk of being caught between conflicting obligations and provides a defensible record in the event of regulatory inquiry.
State laws also have extraterritorial reach. California';s CCPA/CPRA applies to businesses that meet certain thresholds and process the personal information of California residents, regardless of where the business is located. Similar extraterritorial scope applies under most other state laws. International companies with no physical presence in the United States may nonetheless be subject to US state privacy law if they collect data from residents of those states through digital channels.
The US data protection landscape is evolving rapidly. Several developments are shaping compliance priorities for businesses operating in the USA.
Federal privacy legislation. Congressional efforts to enact a comprehensive federal privacy law have continued, with proposals that would preempt state law to varying degrees and establish uniform national standards. The outcome of these efforts remains uncertain, but businesses should monitor legislative developments closely, as federal legislation could significantly alter the compliance landscape.
Artificial intelligence and automated decision-making. Regulators at both the federal and state levels have focused increasing attention on the use of personal data in AI systems. The FTC has issued guidance on AI and has brought enforcement actions involving algorithmic systems. Several state privacy laws now require data protection assessments for profiling activities and impose transparency obligations on automated decision-making. Colorado has enacted specific rules on the use of AI in consequential decisions, and other states are expected to follow.
Health and location data. Following changes in the legal landscape around reproductive health, several states have enacted laws specifically protecting health data and precise geolocation data outside the HIPAA framework. Washington';s My Health MY Data Act is the most prominent example, imposing strict requirements on the collection and sharing of consumer health data by entities not covered by HIPAA. Similar laws have been enacted in Nevada and Connecticut, and more are expected.
Children';s privacy. Federal and state regulators have intensified scrutiny of data practices involving minors. The FTC has proposed significant updates to COPPA rules. Several states, including California, have enacted age-appropriate design codes that impose additional obligations on online services likely to be accessed by children, including requirements to assess privacy risks to minors and to default to privacy-protective settings.
Data broker regulation. States including California, Vermont, Texas, and Oregon have enacted laws requiring data brokers to register with state authorities and, in some cases, to honour deletion requests submitted by consumers through a centralised mechanism. The California Delete Act, for example, requires data brokers to honour deletion requests submitted through a state-operated platform.
In practice, founders and compliance officers should consider building a rolling review process into their privacy programme - at minimum annually, and more frequently as new state laws take effect or regulatory guidance is issued.
---
Does a foreign company with no US office need to comply with US state privacy laws?
Yes, in many cases. Most US state privacy laws apply based on the residency of the consumers whose data is processed, not the location of the business. A company based outside the United States that collects personal information from California residents through a website, app, or other digital channel may be subject to the CCPA/CPRA if it meets the applicable thresholds - for example, processing the personal information of a certain number of California residents annually or deriving a defined proportion of revenue from selling personal information. Similar extraterritorial logic applies under Virginia';s, Colorado';s, and most other state laws. Foreign businesses should conduct a threshold analysis before assuming they fall outside the scope of US state law.
How long does it take to build a compliant US privacy programme, and what does it cost?
The timeline and cost depend heavily on the size and complexity of the business, the volume and sensitivity of data processed, and the number of state laws that apply. For a mid-sized company entering the US market, a baseline programme - covering data mapping, privacy notice drafting, consumer rights procedures, vendor contract review, and staff training - typically takes several months to implement properly. Professional fees for legal and compliance advisory work vary widely; businesses should budget for ongoing costs as well as initial setup, since the regulatory landscape changes frequently and programmes require regular updating. Companies that attempt to build a programme without specialist input often discover gaps later, at the point of a regulatory inquiry or consumer complaint, when remediation is more expensive.
Is a Data Protection Officer required under US law?
No US federal or state privacy law currently mandates the appointment of a DPO as a matter of domestic law. However, companies subject to the EU';s GDPR - because they process data of EU residents - may be required to appoint a DPO under that regulation, depending on the nature and scale of their processing activities. Many US companies with significant data operations appoint a Chief Privacy Officer or equivalent role voluntarily, both to manage regulatory relationships and to provide internal accountability. Some state privacy laws require businesses to designate a contact for consumer requests, which is a lighter obligation than a formal DPO role but serves a similar transparency function.
---
Data protection in USA is a multi-layered compliance challenge that requires businesses to navigate federal sector-specific laws, a growing number of state comprehensive privacy statutes, and cross-border transfer mechanisms for international data flows. The landscape is changing quickly, with new state laws taking effect regularly and federal legislative and regulatory activity intensifying. Companies that treat privacy compliance as a one-time exercise rather than an ongoing programme face material legal and reputational risk.
VLO Law Firms advises international clients on data protection matters in the USA. We can assist with privacy programme design, state law compliance mapping, cross-border transfer arrangements, regulatory response, and vendor contract review. To request a consultation, contact: info@vlolawfirm.com